Malware

Should I remove “Zusy.426797”?

Malware Removal

The Zusy.426797 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.426797 virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Zusy.426797?


File Info:

name: FAB5C6A462437F6708EB.mlw
path: /opt/CAPEv2/storage/binaries/8ad2f7a9c4b190aac0ae339f7cefdec3ffc5d762a01fa35b4842cfddb26bbade
crc32: 49F0B949
md5: fab5c6a462437f6708eb035e295920c4
sha1: 9551210b4d2102d65e91ea5be2268b3036205972
sha256: 8ad2f7a9c4b190aac0ae339f7cefdec3ffc5d762a01fa35b4842cfddb26bbade
sha512: 19d93268adf121d2ace43b6d5a63f6a9a275ef26a705f16c7f2602ff8f10813ac8613d0d316d84102e76312a8daac5274d4a4d6f0d0d9dbb7d6912d1f4e2dbfc
ssdeep: 192:y3ClpBJjYo7aahQzdk/3u+ZIosZKmBGb4k:NpBJEWaahQxk/3eol7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14EF397427EAD2BAFC0110674D76386270E27AC7006699243599CFF6FEC46E125A2F726
sha3_384: 078b6bf9231f0d75f2a47fc133960b571617e06f91b8928e9e1f4e2c1f8174c7c68f72ea9728fa08a53f0caa87c1b23e
ep_bytes: 60be00804c008dbe0090f3ff5783cdff
timestamp: 2011-09-08 10:56:41

Version Info:

0: [No Data]

Zusy.426797 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Zusy.426797
FireEyeGeneric.mg.fab5c6a462437f67
SkyhighArtemis
ALYacGen:Variant.Zusy.426797
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Zusy.426797
SangforTrojan.Win32.Save.a
BitDefenderGen:Variant.Zusy.426797
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36792.jmW@a4OSaghb
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
CynetMalicious (score: 100)
APEXMalicious
KasperskyVHO:Trojan.Win32.Sdum.gen
SophosTroj/Agent-BBCQ
F-SecureTrojan.TR/Crypt.ULPM.Gen
ZillyaTrojan.GenericML.Win32.573
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Zusy.426797 (B)
IkarusTrojan-Dropper.Agent
JiangminTrojan.GenericML.dr
WebrootW32.Trojan.Gen
VaristW32/S-8ef799f6!Eldorado
AviraTR/Crypt.ULPM.Gen
Kingsoftmalware.kb.b.969
MicrosoftTrojan:Win32/Wacatac.B!ml
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Zusy.D6832D
ZoneAlarmVHO:Trojan.Win32.Sdum.gen
GDataGen:Variant.Zusy.426797
GoogleDetected
AhnLab-V3Trojan/Win32.Bjlog.R11765
Acronissuspicious
McAfeeArtemis!FAB5C6A46243
MAXmalware (ai score=83)
DeepInstinctMALICIOUS
Cylanceunsafe
SentinelOneStatic AI – Malicious PE
FortinetW32/Generic.AC.3F7A8C!tr
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.b4d210
AvastWin32:BackdoorX-gen [Trj]

How to remove Zusy.426797?

Zusy.426797 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment